CVE-2020-21356: Popojicms

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

Affected products

Published 2021-08-06. Last modified 2026-06-17.